Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> Security - PHP Nuke
Author Message
sixonetonoffun
Spouse Contemplates Divorce


Joined: Jan 02, 2003
Posts: 2496

PostPosted: Fri Apr 09, 2004 5:30 pm Reply with quote

While doing well something today. I found a what I call trivial path disclosure bug in AvantGo.

Simply type in the sid= the number of a deleted article like this:
modules.php?name=AvantGo&file=print&sid=27
Where 27 was removed and you get:
Warning: mysql_fetch_row(): supplied argument is not a valid MySQL result resource in /home/user_name/public_html/includes/sql_layer.php on line 286

This is not itself a big deal but its a piece of the puzzle and should be addressed. I'm sure its not the last bug but its certainly another.
 
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 17086

PostPosted: Fri Apr 09, 2004 11:43 pm Reply with quote

Looks like this one Only registered users can see links on this board! Get registered or login!
 
View user's profile Send private message
sixonetonoffun
PostPosted: Sat Apr 10, 2004 1:10 am Reply with quote

I thought it sounded familar but the site I noticed it on was one I would have believed fully patched. As the person is a rather well known shaker and rabble rouser in that community. Been kicked off more sites then me wink*
 
Display posts from previous:       
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> Security - PHP Nuke

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©